SIM Swapping
A social-engineering attack in which a criminal convinces or bribes a mobile carrier to transfer a victim's phone number to a SIM card the attacker controls, intercepting calls and SMS one-time passwords.
Definition
SIM swapping, also called SIM hijacking, is a form of social engineering in which an attacker persuades or bribes a mobile network operator's staff, or exploits weaknesses in the operator's identity verification process, to transfer a victim's phone number onto a SIM card the attacker physically controls. Once the number is ported, the victim's phone loses service entirely while the attacker begins receiving all calls and SMS messages meant for that number, including the one-time passwords many banks and online services use to verify identity.
An attacker typically begins by gathering personal information about the target, often through prior data breaches, social media, or a pretexting phone call to the victim directly, in order to pass the carrier's identity checks. They then contact the mobile carrier, either in person, by phone, or sometimes through a bribed insider, claiming to be the victim reporting a lost or damaged SIM and requesting the number be moved to a new SIM card. If the carrier's verification is weak or the attacker's social engineering succeeds, the number is ported within minutes and the victim's phone suddenly shows no signal.
The damage from a successful SIM swap escalates quickly because so many account-recovery and login flows still rely on SMS as a second factor or as the sole recovery mechanism. With control of the phone number, an attacker can reset passwords on email, banking, and cryptocurrency accounts by intercepting the SMS codes sent to verify the change, often draining accounts before the victim even realizes their phone has stopped working. In Indonesia, where SMS one-time passwords remain widely used for mobile banking and e-wallet verification, SIM swapping has been directly linked to significant fraud losses and is a growing concern for regulators.
The strongest defense is moving away from SMS as an authentication or recovery method wherever possible, replacing it with an authenticator app, a hardware security key, or a passkey that is not tied to the phone number at all. Setting a PIN or additional verification requirement directly with the mobile carrier for any SIM change request adds friction that stops casual social-engineering attempts. Noticing a sudden and total loss of phone signal, especially alongside unexpected account-recovery emails, is often the first and only warning sign before an attacker moves quickly to lock victims out of their accounts.
At a glance
- Severity
- High
- Prevalence
- Common, especially against high-value targets
- Primary targets
- Mobile phone numbers used for SMS one-time passwords
- Also known as
- SIM hijacking, SIM jacking
How it works
- 1
Information gathering: the attacker collects personal details about the victim from breaches, social media, or a pretexting phone call.
- 2
Carrier contact: posing as the victim, the attacker contacts the mobile carrier claiming a lost or damaged SIM and requests the number be transferred.
- 3
Social engineering or bribery: the attacker convinces carrier staff to bypass or weakly verify identity, or in some cases bribes an insider to complete the port.
- 4
Number ported: the phone number is moved to a SIM the attacker controls, and the victim's phone loses signal entirely.
- 5
Interception: the attacker now receives all calls and SMS messages meant for the victim, including one-time passwords.
- 6
Account takeover: using intercepted SMS codes, the attacker resets passwords and takes over email, banking, or cryptocurrency accounts.
Warning signs
- Sudden, total loss of mobile signal or the message "no service" with no known cause such as travel or a carrier outage
- An unexpected text or email confirming a SIM change or number transfer you did not request
- Password-reset or account-recovery emails you did not initiate arriving in quick succession
- Being unable to receive calls or texts while your phone otherwise appears to work normally
- Notifications from your bank or e-wallet about a login or transaction you did not perform
How to defend
- Move away from SMS-based one-time passwords in favor of an authenticator app, hardware security key, or passkey wherever an account allows it
- Set a PIN or passcode directly with your mobile carrier that must be provided before any SIM change is processed
- Limit the personal information shared publicly on social media that could be used to pass a carrier's identity check
- Contact your carrier immediately if your phone unexpectedly loses signal for an extended period
- Enable account-recovery alerts on email and financial accounts so any unauthorized reset attempt is flagged quickly
- Prefer app-based push authentication or passkeys for banking and email over SMS wherever offered
Real-world example
An attacker researches a bank executive's social media accounts and pieces together enough personal details to convince a mobile carrier's call center that they are the executive reporting a lost phone. The carrier transfers the executive's number to the attacker's SIM. Within the hour, the attacker uses intercepted SMS codes to reset the password on the executive's personal email account, then pivots to reset banking credentials before the executive notices their phone has no signal.
How Claro helps
Claro's vishing and social-engineering simulations train employees to recognize the pretexting techniques attackers use to gather the personal details needed for a SIM swap, while awareness content encourages a shift toward authenticator apps and passkeys over SMS for any account that supports it, closing off the underlying weakness SIM swapping exploits.
Frequently asked questions
What is SIM Swapping?
SIM swapping is a fraud where an attacker convinces a mobile operator to transfer a victim's phone number to a SIM they control, letting them intercept SMS one-time passwords and take over accounts.
What is SIM swapping used for?
Mainly to intercept SMS-based one-time passwords and account-recovery codes, letting an attacker reset passwords and take over email, banking, or cryptocurrency accounts tied to the victim's phone number.
How do I know if I have been SIM swapped?
The clearest sign is a sudden, total loss of mobile signal with no explanation, often alongside unexpected account-recovery emails or texts confirming a SIM change you did not request. Contact your carrier immediately if this happens.
Can SIM swapping be stopped with a strong password?
No. SIM swapping bypasses the password entirely by taking over the phone number used for account recovery and SMS verification, so even a strong password can be reset once the attacker controls your number.
What is the best protection against SIM swapping?
Moving your accounts away from SMS-based verification toward an authenticator app, hardware security key, or passkey removes the phone number as a single point of failure, and setting a carrier PIN adds another barrier against the transfer itself.
Related terms
Account Takeover
When an attacker gains unauthorized control of a user's online account, typically through stolen credentials, and uses it for fraud or further attacks.
Vishing
Vishing is a voice-based social engineering attack where a caller impersonates a trusted party over the phone to trick victims into revealing sensitive information or authorizing fraudulent actions.
Multi-Factor Authentication (MFA)
A security method that requires two or more independent proofs of identity before granting access to an account or system.
Social Engineering
The manipulation of people into revealing sensitive information or taking unsafe actions by exploiting trust, emotion, and human psychology rather than technical flaws.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo